this post was submitted on 11 Mar 2025
47 points (100.0% liked)

Fediverse

385 readers
78 users here now

Federated universe is a decentralized, federated social media network that is interoperable with each other by using ActivityPub protocol.


Rules

1. English onlyTitle and associated content has to be in English.
2. Respectful communicationAll communication has to be respectful of differing opinions, viewpoints, and experiences.
3. InclusivityEveryone is welcome here regardless of age, body size, visible or invisible disability, ethnicity, sex characteristics, gender identity and expression, education, socio-economic status, nationality, personal appearance, race, caste, color, religion, or sexual identity and orientation.
4. Ad hominem attacksAny kind of personal attacks are expressly forbidden. If you can't argue your position without attacking a person's character, you already lost the argument.
5. Off-topic tangentsStay on topic. Keep it relevant.
6. Instance rules may applyIf something is not covered by community rules, but are against lemmy.zip instance rules, they will be enforced.


Interesting links

Icon by Eukombos (CC0)


If someone is interested in moderating this community, message @brikox@lemmy.zip.

founded 10 months ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] henfredemars@infosec.pub 22 points 23 hours ago (2 children)

And we’re able to talk about it on the same platform on another instance. All in all, a success IMHO.

[–] AbnormalHumanBeing@lemmy.abnormalbeings.space 7 points 23 hours ago* (last edited 23 hours ago) (1 children)

I guess in theory, malicious actors have some options trying to target and overload all of the Fediverse, but I don't think any are really feasible. At the point, where you could take out the (vast majority of) nodes with something like a DDOS, you already had enough resources to spare, to take out just significant parts of the overall internet altogether.

0-day exploits could of course be problematic, as they are for anything, but even then, using one on all (or then majority of) nodes simultaneously, and/or distributing a payload to all/the majority of nodes is also just so much effort. Also, chances are quite low you will get an exploit for all platform software, and if it targets something in ActivityPub, then all you can do at best is stifling federation, I guess, still allowing for local content to remain up.

Not only censorship resilient and with dynamic interlocking communities, also pretty damn resilient when it comes to overall uptime security.

[–] b1t@lemm.ee 12 points 23 hours ago

If someone is burning 0days for fucking Lemmy they seriously need to get some help and re-evaluate their life choices lol

[–] Rhaedas@fedia.io 5 points 23 hours ago (1 children)

The biggest limitation left is for users of that instance. The workaround is to make accounts on one or more different instances, even often with the same handle just different addresses. Then you most likely can get back to consumption until your main account is working again. The caveat is there isn't a way (yet*) to share a lot of the info between those accounts to make it feel less like a temp account. Still far better than refreshing a singular website status page over and over.

  • yet or even if it's practical. I know some played with a few importing ideas early on for themes and I think subscriptions, but I doubt anything more. History and such would open a lot of security issues.
[–] henfredemars@infosec.pub 2 points 21 hours ago

I’ve definitely taken the main and back up approach. Not perfect, but it’s worked reasonably well.